Published on · By the IT LABS PRO team
As soon as your website collects a name, an e-mail address or a phone number, it processes personal data. In Morocco, law no. 09-08 on the protection of individuals with regard to the processing of personal data governs this processing, and the CNDP (Commission nationale de contrôle de la protection des données à caractère personnel, the national data protection commission) oversees its application. Here is what it means in practice for a website. This article is a general overview: for your specific situation, refer to the CNDP’s publications or to a legal adviser.
What is personal data?
Personal data is any information that identifies an individual, directly or indirectly: name, e-mail address, phone number, postal address, and in some cases an IP address or a cookie identifier. A simple showcase website with a contact form is therefore concerned.
Common processing on a website
- Contact and quote forms;
- Newsletter sign-ups;
- Customer accounts and online orders;
- Visitor statistics and audience measurement tools;
- Advertising cookies and retargeting tools;
- Job applications received through the website.
Obligation 1: declare your processing or have it authorised
Law 09-08 builds compliance around prior formalities with the CNDP: before starting to process personal data, the controller must, depending on the case, declare the processing or obtain an authorisation. The CNDP provides forms and online notification procedures, including forms for a standard prior declaration and a simplified declaration depending on the type of processing. See the “Formalités” section of the CNDP website to find the right procedure for each of your processing activities.
Obligation 2: inform people
Visitors must know who collects their data, why, who receives it, how long it is kept and how to exercise their rights. In practice:
- a complete “Privacy policy” page, reachable from every page;
- a short notice at each collection point (under the form, at sign-up) that sums up the essentials and links to the full policy;
- the website’s legal notice, which identifies the publisher.
Our free privacy policy generator for law 09-08 gives you a starting text in a few minutes.
Obligation 3: get consent when it is required
For some uses, in particular electronic marketing or setting cookies that involve personal data, the visitor’s consent must be obtained. According to the CNDP’s guidelines on website compliance, a website that uses such cookies must obtain consent before setting them, state their purpose and explain how to refuse them. A clear cookie banner with the option to refuse meets this requirement.
Obligation 4: respect people’s rights
The people concerned have, in particular, the rights of access, rectification and objection. Explain how to exercise them (a dedicated e-mail address, for example) and be organised to answer within a reasonable time.
Obligation 5: secure the data
The controller must take the necessary measures to protect data against loss, unauthorised access or disclosure. For a website:
- the whole site served over HTTPS;
- regular security updates for the site and its plugins;
- admin access protected by strong passwords;
- regular backups;
- only the data you really need, kept for a justified period;
- care with data transfers abroad (hosting, third-party tools), which follow specific rules.
Compliance checklist for your website
- List the data your website collects (forms, accounts, cookies, third-party tools).
- For each processing activity, identify the formality to complete with the CNDP.
- Write or update your privacy policy and legal notice.
- Add a short information notice under each form.
- Set up consent management for the cookies concerned.
- Provide an address or another way to exercise rights.
- Check security: HTTPS, updates, access, backups.
- Document your choices and review them every time the website changes.
E-commerce websites
An online shop processes more data: identity, delivery addresses, order history, sometimes payment data. Card details must never be stored on your website: the payment gateway handles them. See our guides to online payment in Morocco and to e-commerce websites in Morocco.
What about your internal tools?
The law also applies to prospect lists, CRMs and management software that contain customer or employee data. If you are setting up a CRM or a management application, build these rules in from the design stage: access rights, retention periods, logging of sensitive access.
Example notice under a contact form
Here is an example of a short notice, to adapt to your situation and complete with your privacy policy:
“The information collected through this form is intended for [company name] to answer your request. It is kept for [period] and is not passed on to third parties. Under law 09-08, you have the right to access, rectify and object to it, which you can exercise by writing to [e-mail].”
Frequently asked questions
Does law 09-08 apply to a simple showcase website?
Yes, as soon as it collects personal data, for example through a contact form or analytics tools that process identifiers.
Where can I find the CNDP forms?
On the CNDP’s official website, in the sections on formalities and notification procedures.
Does a website in Morocco need a cookie banner?
If your website sets cookies that involve personal data (advertising, some measurement tools), the CNDP’s guidelines call for obtaining consent before setting them, stating their purpose and explaining how to refuse them.
In short
Any website that collects personal data must complete the formalities with the CNDP, inform visitors clearly, obtain their consent when needed, respect their rights and secure the data. IT LABS PRO builds these technical requirements (forms, notices, cookie management, security) into the websites it delivers: discover our website development in Morocco.
